Re: [Security-Discuss] Xine accessing /etc/passwd ????
Tuxiq <tuxiq2304-FFYn/[email protected]> Mon, 22 May 2006 13:30:59 -0400
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
On Mon May 22 2006 04:07 am, Michael Scherer wrote: > > Sorry Michael, but who is overreacting here? I was just trying to bring > > attention to the point of the message which was, my wondering if it was > > normal behaviour. > > Well, I have no problem with the question by itself, just with the form of > final part of the question. Just as I had reservations with your commenting about it right off the bat... reservations which I left out of my previous replies. Even though that was my first posting here, it wasn't my first posting ever in a mailing-list. I started out long ago in FIDONET well before the internet existed. And in my time, etiquette dictated reserving such comments for the bottom of the message, as a BTW, precisely to avoid newbees feeling like they'd made a terrible mistake and risking scaring them away for good. Answering to the actual content of the message BEFORE comdemning its form was considered a more diplomatic avenue, easing the newbee in, without rustling his fragile feathers ;-) > how do you know it read only the root entry ? > > if this is because you have seen a line with the read syscall, then, again, > this is normal because the whole file is read at once, but strace only show > the beggining of what is read. Yes, and you'll see I'd just sent a reply pointing out my mistake just before receiving this one > As far as i know, we are on a mandriva related list. And I never seen any > mandriva system without shadow password. I am not even sure they started to > use since the beggining. > If you run xine, i strongly suspect you are running it on something newer > than 9.0 You are assuming again... remember there are still people using older systems simply because newer ones my have incompatibilities to their hardware etc... And before Mandriva there was Mandrake and I seem to remember having the option to use shadow files or not my choice... Mind you I've been using Mandrake since release 7 or 8 > if you think this is a bug, then, bugzilla is the tool to use. Well what I have been trying to get you to understand is that the end result could have been caused by either... So my safest course of action was to raise the question here, where experts could confirm it one way or another. > what version of xine ( rpm -q xine-ui ), To those not paying attention... see earlier in this post... > do you reproduce it on other > computer ? Reproduceable at will on this machine, don't have another one to try it on yet. But your question reminds me I tested just starting xine and exiting without actually playing nor providing a filename on the command line. No "mkdir" message then. Which would seem to confirm it is some kind of history or playlist preservation that is part of the exit procedures. > I see this on cooker as well, but i do not think this is a security > problem. Yes, I mentionned a hack was only a slight possibility but a possibility none the less which had to be mentionned. As I said again and again, though not in those words... Hindsight is allways 20/20 ! > And, from what i see, xine in cooker is not patched, so this is likely a > problem in xine code than a patched version or a hack. > > You should report it to xine developers, and see if this was not already > referenced in their bugs database, if they have one. Stew Benedict mentionned he is working on xinelib and noticed the bug earlier too. Thanks again, Lets put this to rest before we waste anymore bandwidth Case closed ;-) Mark (Aka Tuxiq aka Tux-IQ) ____________________________________________________ Want to buy your Pack or Services from Mandriva? Go to http://store.mandriva.com Join the Club : http://www.mandrivaclub.com ____________________________________________________